Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5368 | Matrix IRC Bridge allows IRC command injection to own puppeted user |
Github GHSA |
GHSA-5mvm-89c9-9gm5 | Matrix IRC Bridge allows IRC command injection to own puppeted user |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Mar 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matrix
Matrix matrix Irc Bridge |
|
| CPEs | cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Matrix
Matrix matrix Irc Bridge |
Tue, 25 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4. | |
| Title | Matrix IRC Bridge allows IRC command injection to own puppeted user | |
| Weaknesses | CWE-77 CWE-88 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T20:33:36.095Z
Reserved: 2025-02-19T16:30:47.778Z
Link: CVE-2025-27146
Updated: 2025-02-25T20:30:57.833Z
Status : Analyzed
Published: 2025-02-25T20:15:38.030
Modified: 2025-03-04T20:42:55.570
Link: CVE-2025-27146
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA